REDHAT-BUG-1382369: Medium severity ntp vulnerability
Multiple bugs in cronjob script bundled with ntp package were found allowing malicious ntp user to make the backup process to overwrite arbitrary files with content controlled by the attacker, thus gaining root privileges.
External References:
http://www.halfdog.net/Security/2015/NtpCronjobUserNtpToRootPrivilegeEscalation/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1382369?
The severity of REDHAT-BUG-1382369 is critical due to possible root privilege escalation.
How do I fix REDHAT-BUG-1382369?
To fix REDHAT-BUG-1382369, it is recommended to update the NTP package to the latest version provided by Red Hat.
Who is affected by REDHAT-BUG-1382369?
Systems utilizing the NTP package with the vulnerable cronjob script are affected by REDHAT-BUG-1382369.
What is the impact of REDHAT-BUG-1382369?
The impact of REDHAT-BUG-1382369 allows malicious users to overwrite arbitrary files, potentially leading to complete system compromise.
Can REDHAT-BUG-1382369 be exploited remotely?
Yes, REDHAT-BUG-1382369 can be exploited remotely by an attacker with access to the NTP service.